Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-16461

Опубликовано: 20 июл. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

A stack-based buffer overflow was found in rpcbind's rpcinfo utility. In rpcbdump() short mode (used by rpcinfo -s), version numbers from a remote RPCBPROC_DUMP reply are written into a fixed-size stack buffer without bounds checking. A user or administrator who runs rpcinfo -s against a malicious or compromised rpcbind endpoint could experience a crash or denial of service of the rpcinfo client.

Отчет

Moderate. This client-side vulnerability in the rpcinfo utility requires a user or administrator to execute rpcinfo -s against a malicious or compromised rpcbind endpoint. Exploitation can lead to a client crash and denial of service for the rpcinfo process.

Меры по смягчению последствий

To mitigate this issue, avoid using the rpcinfo -s command against untrusted, attacker-controlled, or compromised rpcbind hosts. Restrict the use of the rpcinfo utility to trusted internal endpoints or secure test environments only.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10rpcbindFix deferred
Red Hat Enterprise Linux 8rpcbindFix deferred
Red Hat Enterprise Linux 9rpcbindFix deferred
Red Hat OpenShift Container Platform 4rpcbindFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-121
https://bugzilla.redhat.com/show_bug.cgi?id=2502719rpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbdump() short-mode version-list formatting

EPSS

Процентиль: 13%
0.00227
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
21 день назад

A stack-based buffer overflow was found in rpcbind's rpcinfo utility. In rpcbdump() short mode (used by `rpcinfo -s`), version numbers from a remote RPCBPROC_DUMP reply are written into a fixed-size stack buffer without bounds checking. A user or administrator who runs `rpcinfo -s` against a malicious or compromised rpcbind endpoint could experience a crash or denial of service of the rpcinfo client.

CVSS3: 6.5
nvd
21 день назад

A stack-based buffer overflow was found in rpcbind's rpcinfo utility. In rpcbdump() short mode (used by `rpcinfo -s`), version numbers from a remote RPCBPROC_DUMP reply are written into a fixed-size stack buffer without bounds checking. A user or administrator who runs `rpcinfo -s` against a malicious or compromised rpcbind endpoint could experience a crash or denial of service of the rpcinfo client.

CVSS3: 6.5
msrc
17 дней назад

Rpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbdump() short-mode version-list formatting

CVSS3: 6.5
debian
21 день назад

A stack-based buffer overflow was found in rpcbind's rpcinfo utility. ...

CVSS3: 6.5
github
21 день назад

A stack-based buffer overflow was found in rpcbind's rpcinfo utility. In rpcbdump() short mode (used by `rpcinfo -s`), version numbers from a remote RPCBPROC_DUMP reply are written into a fixed-size stack buffer without bounds checking. A user or administrator who runs `rpcinfo -s` against a malicious or compromised rpcbind endpoint could experience a crash or denial of service of the rpcinfo client.

EPSS

Процентиль: 13%
0.00227
Низкий

6.5 Medium

CVSS3